CVE-2013-5108: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the xn function in RockMongo 1.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) db parameter on the login page or (2) username parameter in a login.index action to index.php and other unspecified parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5108?
CVE-2013-5108 has been classified with a medium severity level due to its potential for exploitation through cross-site scripting.
How do I fix CVE-2013-5108?
To fix CVE-2013-5108, upgrade RockMongo to version 1.1.6 or later, which addresses the XSS vulnerabilities.
What are the affected versions in CVE-2013-5108?
CVE-2013-5108 affects RockMongo versions 1.1.5 and earlier.
What types of attacks can CVE-2013-5108 facilitate?
CVE-2013-5108 can facilitate cross-site scripting (XSS) attacks, allowing attackers to inject arbitrary scripts or HTML.
Is CVE-2013-5108 specific to a certain function in RockMongo?
Yes, CVE-2013-5108 specifically exploits the xn function in RockMongo.